Vulnerability in Oracle E-Business Suite's Shopping Cart Component
CVE-2020-2582
8.2HIGH
Summary
An unauthenticated attacker with network access via HTTPS can exploit a vulnerability in Oracle iStore, part of Oracle E-Business Suite. This vulnerability allows for unauthorized access to sensitive data stored within the iStore, including the ability to update, insert, or delete accessible data. Successful exploitation requires human interaction from an individual other than the attacker, further complicating the risk scenario. As the vulnerability resides in the shopping cart component, it may have downstream impacts on other products within the E-Business Suite, potentially leading to significant data loss or compromise.
Affected Version(s)
iStore 12.1.1-12.1.3
iStore 12.2.3-12.2.9
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved